ESG had an underground update a few years ago that is growing in popularity, because, well, it just makes sense. Some even say that without adding the ‘+R’, ESG as a whole is worthless. The +R adds a "Resilience" pillar to ESG, and some of the frameworks already ask to report on it. TCFD, TNFD, IFRS S2, and CDP now require a narrative on how resilient a company's strategy is against climate or nature scenarios. However, none of them score it, give a practical evaluation framework, or treat resilience as a property of a system (which is the only way it can be understood properly) rather than a single company's story. Luckily, SiD already included Resilience 15+ years ago, and we can tap into its vast documentation, frameworks, and tools to help shape what ‘+R’ means for organizations, policies, products and strategies.
The idea of ‘+Resilience’ traces to a June 2021 World Economic Forum piece, by Judith Rodin and Sadia Madsbjerg, arguing that resilience is the "missing piece" ESG needs, since investors can't tell which portfolios can withstand systemic shocks without it. That WEF argument was picked up and popularized through 2021–2022 by consultancies and industry webinars (e.g. Fusion, 2021), then by sector-specific adopters like commercial real estate and trade bodies. The National Association of Realtors now publishes an annual "Environmental, Social, Governance and Resilience (ESG+R)" report as one of its four core sustainability pillars.
As a consequence, some of the mainstream ESG frameworks, such as TCFD, now ask companies to describe the resilience of their strategy against a 2°C warming scenario. TNFD asks the same question about nature. IFRS S2 turned the climate version into a disclosure requirement, and CDP put it into its annual questionnaire. As a consequence, Resilience is now already a line item in ESG reporting cycles of several multinational organizations. It certainly isn't for SMEs however, and how to actually measure and/or report on Resilience is a big question mark for all of them.
The instinct on resilience is right. A company's capacity to survive a shock deserves its own analysis, evaluation, and strategy. But it should be more than a paragraph buried inside general risk management.
The World Economic Forum's Global Risks Report 2026 is blunt about why this is happening now: “relative resilience breaks down under unprecedented turbulence.” And turbulence is what we're certainly experiencing now, worldwide, in virtually every market.
The Resilience Question
Take a look at what TCFD, TNFD, IFRS S2, and CDP actually ask for. A company picks a handful of climate or nature scenarios, a 2°C world, a 4°C world, a nature-positive pathway, and writes a narrative about how its strategy holds up in each. TCFD calls this its Strategy pillar. TNFD built its own version, Strategy C, on top of it.
IFRS S2 made the climate question mandatory for companies with material exposure. CDP asks the same question again in its annual questionnaire, scoring the answer A through D-. All four are asking about one hazard family at a time, which is problematic, since resilience is a systemic and emergent property of the whole of the organization in relation to the whole of its systemic context, and not a per-department characteristic.
A written scenario narrative is not the same thing as a systemic analysis. It can be any story woven to sound convincing enough. It says nothing about resilience to, oh to name a few, pandemics, cyberattacks, geopolitical rupture, or social unrest, if they were not part of the systemic analysis. It says nothing per se about the resilience of the supply chains, ecosystems, and communities the company actually depends on. And that there is the whole point: an organization cannot make a profit, or even survive, if the societal structure it is in collapses. Resilience therefore fundamentally relies on an analysis of an organization's context, and the fit of the organization within it. It is not an inside-out only characteristic.
The Lure of Narrow Definitions of Resilience
Unfortunately, the GRI, the most widely used sustainability reporting standard, does not even have a resilience-specific disclosure. Resilience only enters a GRI report if a company names it as material on its own initiative, with no shared definition or scoring guidance to draw on. With the GRI notably absent, including Resilience needs to rely on some other definition or framework to have some sort of compliance. Unfortunately, virtually all of them are lured by an overly simplistic definition, which defeats the purpose of looking at Resilience in the first place. Most tools mentioned in this article fall into one of three buckets.
- Narrative strategy-resilience. TCFD, TNFD, IFRS S2, and CDP: a scenario-tested story, not scored, limited to a single hazard family.
- Operational continuity. ISO 22301 and ISO 22316: guidance only, no scoring, doesn't reach past the organization's own boundary.
- Rating-embedded branding. MSCI and S&P Global use resilience as framing, not a separate score. The exception: MSCI's Government Ratings, scoring “resilience to natural hazards and climate risks” for sovereigns only.
None of the three treats resilience as a property of a system. As the Resilience Alliance's Handbook of Practitioners says very clearly: “Resilience is fundamentally a system property.” Then, how can an ESG officer deal with this?
Present Tools not Suitable for a Company
Two efforts are systemic in scope, but at the wrong scale for a company. The Sendai Framework tracks 38 indicators across seven global targets, is meant for disaster prevention in nation states. The City Resilience Index, built by Arup with the Rockefeller Foundation, scores 52 indicators for entire cities. Neither was built for a company's annual report.
Two other efforts are scientifically rigorous but too heavy for a disclosure cycle. The Resilience Alliance publishes a practitioner workbook, which is immensely useful, but it is a very heavy instrument that runs over months for Resilience alone. Albeit, it is the most useful resource mentioned so far.
No framework surveyed combines systemic scope, scientific rigor, and a workable annual cycle. That gap is exactly where an ESG professional finds themselves. But, there is a framework that has been integrating Resilience for over two decades, which is built for creating a Sustainability Strategy rather than ESG reporting: SiD.
Resilience, Autonomy, Harmony
Symbiosis in Development (SiD) is the systems framework developed by Except since 1999, in practice across industries to work on systemic strategy and innovation. It names resilience as one of three system-level indicators, alongside Autonomy and Harmony (together RAH). The SiD manual defines it directly: “Resilience is a system's capacity to withstand (unexpected) external disturbances and its ability to return to a healthy state after suffering a blow.” ThinkSiD's documentation adds: the return is “not necessarily the same state as before.” That clarifies resilience as a capacity to reorganize and keep flourishing in a changed state.
In SiD, Resilience, Autonomy, and Harmony are the main three system indicators for sustainability in the SiD system. All three interact, and each one shifts when either of the others does. The book's alien colony: to survive an asteroid, the colony needs to detect it coming (awareness), get out of the way in time (flexibility), and have enough members that a direct hit does not end the colony outright (redundancy). Swap the asteroid for a supplier bankruptcy or a cyberattack. “Resilience responds to Autonomy and Harmony strongly, but not in a linear fashion.”
SiD's system-level chapter on resilience predates the ESG+R term by well over a decade. Its health-systems work applies the same definition to the human body: “the state of the system needs to be resilient, which means that one can recover fairly quickly and sustainably after some imbalance.”
Because SiD has included Resilience for such a long time, ample case studies and tools are available across industries, project sizes, and application areas. For all of them, the critical aspect is to regard Resilience as a property of the whole system, which includes but cannot only be confined to the organization itself. Balancing what is and is not considered as part of the system to review, is therefore an important step in the process.
The SiD Resilience Starting Parameters
To practically work with Resilience, (as well as Autonomy and Harmony, which are equally important but still missing from ESG+R), the system needs to be mapped. SiD gives a standard set to dissect resilience of the organization in relation to its surrounding system to start off with. It also encourages the team to look beyond these terms, or to rephrase them where necessary. The terms can also be evaluated numerically to arrive at quantification tools, but stresses that in each case, this will be a different quantification, and it does not presuppose that a general formula can be created.
The resilience network parameters are named CRAFTDCCV as a particularly un-sexy acronym. These nine parameters can be scoreable high or low for quick analysis, for any network a company depends on: a supply chain, a workforce, an energy system, a stakeholder network, etc. They are called ‘starting parameters’ because they are rarely complete, but they will get you going a long way.

SiD groups the nine into three types:
- Structure (the shape of the network): Connectivity, Redundancy, Centrality
- Character (how fast and varied it is): Flexibility, Diversity, Complexity
- Content (the quality of what moves through it): Awareness, Transparency, Validity
Each parameter comes with an indication on whether more is better. For example, Connectivity is “the level at which the nodes or agents in a system are connected to one another,” and in most cases, more is better, up to the cost of maintaining it. Low Redundancy “leads to a fragile system, which can easily fail due to the breaking of a single critical component or connection.” Complexity runs the other way: past a certain point, “a high Complexity usually makes a system fragile.”
The Content group, Awareness, Transparency, Validity, works on the information moving through a network. “Low Awareness negatively impacts the Resilience of a system, since those agents that do not know about the best ways to respond to critical events may make uninformed decisions and make the situation worse.” Its illustration is Chernobyl, where the operators running the emergency stop did not know it could trigger the meltdown it was meant to prevent. A supply chain team unaware of a single-source dependency fails the same way. The team at Except has seen that example within companies at least half a dozen times.
Scoring well on one parameter alone proves little. A supply chain can score high on connectivity and still be fragile, if centrality is high and redundancy is low: a single supplier away from failure.
Resilience Evaluation in Practice
In practice, a Resilience evaluation follows various stages, each doing a complete review, but each stage going a level deeper. This also allows for throttling the time and effort spent, and the level of detail regarded. This allows quickscans alongside deep analysis. In each phase, the steps are roughly the same:
- Determine the system boundary. A multinational's boundary is vastly different from a local woodshop. That said, supply chains easily ripple across the globe. The system boundary is therefore best evaluated in stages of connectivity, rather than in geographical scale.
- Determine the major chains of cause and effect in all material elements across the ELSI8 categories (Energy, Materials, Ecosystems, Biodiversity, Culture, Economy, Health, Happiness). Review each major chain across each of the nine CRAFTDCCV parameters: high, medium, or low. Reframe the parameter to make sense in context where necessary. Not all parameters always have a meaningful interpretation.
- Investigate the pattern across all nine, and look for co-dependencies across them, and try to be aware of emergent system dynamics (the SiD manuals suggest 12 initial system dynamics to be aware of for each).
- Conclude the patterns and review with relevant stakeholders to gain knowledge from the actors within the system about emergent dynamics.
Based on the outcome, a strategic insight is gained of the organization, its presence now and its future pathways, more so than most other management tools will. This process is therefore not just useful for an ESG+R report, it is materially insightful for the management team to understand how to follow a pathway to flourish in increasingly disruptive times.
'Resilience' understanding changes the strategy
A typical outcome of a Resilience analysis is choosing between growth and resilience as the organization's central strategy. Growth-focused organizations chase short-term expansion, then hit a point where “eventually it will either shrink or run into a resource shortage.” Resilience-focused organizations take a different path.
A company chasing growth and profit “may succeed in doing so for a while,” until an unexpected shock arrives it never prepared for. SiD offers optimization tips that experience has shown to be valuable in most cases:
- Decentralize. “Decentralize units and departments to serve local demand better. Decentralization may trump efficiency, opposing what the P&L spreadsheet may say.”
- Increase flexibility. “Ironclad rules are a sure-fire way to kill resilience. Be nimble, not concrete.”
- Prevent solidity. “Something that is resilient jumps out of the way before it gets hit. For this, it needs speed, awareness, agility, and flexibility.”
- Diversify. “Diversity is getting more important than ever. Diversity in staffing, product, supply, etc.”
Several system parameters may bite each other, even though a high score on both looks better in isolation. For example, a highly efficient network (seems good?) may not have the Redundancy to be a resilient one. Efficiency and Resilience may be opposed at times.
How to get started
The thinkSiD website has online documentation, books, case studies, and training materials on SiD's resilience tools, and the main SiD omnibus manual (free, open source), has details and case studies. Its Anatomy of a System page covers RAH in more depth.
To conclude, ESG+R is right to add a fourth pillar. What frameworks are missing is a way to score the system underneath the narrative. SiD's RAH and CRAFTDCCV parameters have done exactly that since long before ESG+R had a name. SiD may also prepare organizations for the inevitable inclusion of Autonomy and Harmony as additional systemic parameters to ESG evaluation, as Resilience without autonomy or harmony is still faring half blind.
For an ESG professional building next year's report, as a quick way to start: keep the TCFD or CDP scenario paragraph, and add a CRAFTDCCV table for the two or three systems the company depends on most. A day or two of work, at best, and a great start to become familiar.
Sept. 11, 2026

